CVE-2016-3729: CSRF
Multiple vulnerabilities were fixed in moodle 3.0.4, 2.9.6, 2.8.12 and 2.7.14 releases.
============================================================================== MSA-16-0013: Users are able to change profile fields that were locked by the administrator
Description: User editing form only disabled the profile fields in UI and did not actually prevent users from editing them Issue summary: Tricky users can change locked profile fields Severity/Risk: Minor Versions affected: 3.0 to 3.0.3, 2.9 to 2.9.5, 2.8 to 2.8.11, 2.7 to 2.7.13 and earlier unsupported versions Versions fixed: 3.0.4, 2.9.6, 2.8.12 and 2.7.14 Reported by: Vadim Dvorovenko Issue no.: MDL-53954 CVE identifier: CVE-2016-3729 Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-53954
============================================================================== MSA-16-0015: Information disclosure of hidden forum names and sub-names.
Description: Name of the inaccessible forum or forum discussion could be disclosed as part of the error message on the subscription page Issue summary: Information disclosure of hidden forum names and sub-names. Severity/Risk: Minor Versions affected: 3.0 to 3.0.3, 2.9 to 2.9.5 and 2.8 to 2.8.11 Versions fixed: 3.0.4, 2.9.6 and 2.8.12 Reported by: Callum Issue no.: MDL-53696 CVE identifier: CVE-2016-3731 Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-53696
============================================================================== MSA-16-0016: User can view badges of other users without proper permissions
Description: Capability check to view other badges was performed for the current user instead for the user whose badges are being viewed Issue summary: Badges code checks viewotherbadges capability in the wrong context Severity/Risk: Minor Versions affected: 3.0 to 3.0.3, 2.9 to 2.9.5, 2.8 to 2.8.11, 2.7 to 2.7.13 and earlier unsupported versions Versions fixed: 3.0.4, 2.9.6 and 2.8.12 Reported by: Tim Hunt Issue no.: MDL-53589 CVE identifier: CVE-2016-3732 Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-53589
============================================================================== MSA-16-0017: Course idnumber not protected from teacher restore
Description: During the course restore teacher could overwrite idnumber even without having the capability to change it Issue summary: Course idnumber not protected from teacher restore Severity/Risk: Minor Versions affected: 3.0 to 3.0.3, 2.9 to 2.9.5, 2.8 to 2.8.11, 2.7 to 2.7.13 and earlier unsupported versions Versions fixed: 3.0.4, 2.9.6, 2.8.12 and 2.7.14 Reported by: Donna Hrynkiw Issue no.: MDL-51369 CVE identifier: CVE-2016-3733 Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-51369
============================================================================== MSA-16-0018: CSRF in script marking forum posts as read
Description: CSRF possible in the URL that marks forum posts as read Issue summary: Forum markposts.php missing sesskey check Severity/Risk: Minor Versions affected: 3.0 to 3.0.3, 2.9 to 2.9.5, 2.8 to 2.8.11, 2.7 to 2.7.13 and earlier unsupported versions Versions fixed: 3.0.4, 2.9.6, 2.8.12 and 2.7.14 Reported by: Andrew Nicols Issue no.: MDL-53755 CVE identifier: CVE-2016-3734 Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-53755
==============================================================================
Other sources
The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What versions of Moodle are affected by CVE-2016-3729?
CVE-2016-3729 affects Moodle versions 2.7.0 to 2.7.13, 2.8.0 to 2.8.12, 2.9.0 to 2.9.6, and 3.0.0 to 3.0.3.
What is the severity of CVE-2016-3729?
The severity of CVE-2016-3729 is classified as high due to the risk of users altering locked profile fields.
How do I fix CVE-2016-3729?
To fix CVE-2016-3729, upgrade Moodle to version 2.7.14, 2.8.12, 2.9.6, or 3.0.4.
What type of vulnerability is represented by CVE-2016-3729?
CVE-2016-3729 is a user privilege escalation vulnerability that allows unauthorized modification of locked profile fields.
What should organizations do to mitigate CVE-2016-3729?
Organizations should immediately apply the recommended updates to their Moodle installations to mitigate CVE-2016-3729.